Scams & Phishing Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,154
6,263
2,168
Germany
ShinyHunters, a prolific cybercriminal group known for large-scale data theft and extortion, says it has breached the FBI and stolen data on thousands of agents and applicants. The hackers made the claim on their dark web leak site, which TechCrunch reviewed, saying they had stolen “sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job.”

404 Media first reported on the breach after receiving a sample of the stolen names, home addresses, and phone numbers of FBI agents and their spouses, and verifying a portion of the stolen data against public records. The hackers say their hack is “not financially motivated,” and are demanding that the FBI remove a report that they say contains false allegations about the group.

The independent publication said the hackers breached an Oracle PeopleSoft server, often used by human resources and recruiters to store job applicants’ personal information, then pivoted to breach an Amazon-hosted government cloud storing the agents and applicants’ data.

ShinyHunters told the publication that they took terabytes of data but did not say what they would do with the information if the FBI does not take down its published report. The stolen data could present a major counterintelligence threat, in which hackers and overseas spies use the information to coerce or extort FBI agents and their families into cooperating with a foreign government.

The hackers reportedly defaced the FBI’s jobs site, which showed at the time of publication that the portal was “currently down for maintenance.” The site also said that the FBI’s special agent applicant portal was also down.

An FBI spokesperson told TechCrunch: “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” When reached by TechCrunch, the ShinyHunters hackers did not say how many people had their information taken, but said that they are “very confident we have data on mostly all of FBI,” and that “a substantial amount of applicants data [is] involved as well.”

This is the second known breach of an FBI system this year after unidentified hackers broke into one of the agency’s systems for managing real-time wiretaps and foreign intelligence-gathering warrants, which could have identified targets of the agency’s surveillance. Separately, FBI director Kash Patel also had his personal email account hacked and leaked by an Iran-backed hacking group called Handala in retaliation for U.S.-led strikes against Iran.
 
Hi Brownie2019, this is a serious and partly corroborated claim, but it should not yet be described as a confirmed breach of the FBI’s internal systems. Some exposed personal records appear genuine; their source, the claimed intrusion path and the scale of the theft remain unverified.

What is established so far​

Reuters partially verified personal details—including Social Security numbers—against credit-bureau records and previously breached data. That supports the conclusion that at least part of the sample contains real information, but it does not prove that ShinyHunters obtained it from the FBI: Reuters could not establish the source of the records.

ShinyHunters claims it exploited a new Oracle PeopleSoft zero-day and stole 2–3 TB covering current and former employees, applicants and internal records. Those details remain the attackers’ account, not independently confirmed findings. The FBI has acknowledged that it is investigating alleged unauthorized activity affecting FBIjobs.gov, rather than confirming the broader breach.

So the careful description is: credible indications of exposed personal data and an incident under investigation, with the claimed FBI origin and full scope still unconfirmed. A genuine-looking sample is evidence, but not a chain of custody—criminal groups can mix newly stolen records with older breached or publicly available data. [1] [2]

Why the possible impact is unusually severe​

If the claimed source and scope are confirmed, this would go well beyond routine identity theft. Home addresses, relatives’ details and applicant records could support targeted phishing, impersonation, harassment, doxxing or coercion. Applicant information may also reveal people whose relationship with the FBI was not otherwise public.

The reported demand to withdraw an FBI report fits extortion or retaliation even if the group says it is not financially motivated. ShinyHunters has publicly framed the operation as retaliation for an FBI FLASH report from May 2026. That explains the group’s stated motive; it does not validate its technical account.

The PeopleSoft zero-day, the alleged pivot into an Amazon-hosted government environment and the 2–3 TB figure should therefore remain labelled as claims until the FBI, Oracle, Amazon or independent incident responders provide technical evidence. [1]

Sources
  1. ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
  2. Hacking group purports to have stolen FBI employee data in cyber attack - ABC News